Skip to main content
AI privacy & safety exposure

Personal data plus AI is a regulated combination. Treat it as one.

AI privacy and safety exposure counsel from Aun & Co.: data-protection duties, safety-relevant deployments and incident posture for businesses using AI.

The moment AI systems process personal data, two exposure lines converge: privacy law — Israel's Protection of Privacy framework and, for many businesses, European rules reaching them through customers and markets — and safety, where automated outputs shape decisions about real people. Consent gathered for one purpose feeding models built for another, profiles generated without a lawful basis, incidents no one is prepared to notify: these are the standing failure modes. The firm maps the exposure, closes the gaps, and prepares the incident posture before the incident.

The work spans
  • Data-flow mapping: which personal data reaches which AI systems
  • Lawful-basis and consent review against actual processing
  • Safety-relevant deployment review: automated decisions about people
  • Cross-border transfer analysis where tools process data abroad
  • Incident and breach posture: readiness before notification clocks start
  • Customer or employee data flows into AI tools and the lawful basis was never mapped to that use.
  • An AI system scores, filters or decides about individuals and no one has reviewed the duties that engages.
  • Your tools process personal data on servers abroad and the transfer position is unexamined.
  • A data incident involving an AI system is conceivable and no playbook exists for the first day.

The firm traces the data, not the marketing: what personal information actually enters each system, under what basis it was collected, what the vendor's terms do with it, and where it travels. Deployments touching people — scoring, filtering, automated decisions — get a second pass for the duties those functions engage. The output is dual: a compliance gap list sequenced by enforcement risk, and an incident playbook, because privacy failures are judged largely on the response.

04 · What you get

The data traced end to end

Actual flows mapped from collection to model — the factual foundation every privacy position stands or falls on.

People-facing uses hardened

Automated decisions about individuals reviewed against the duties they trigger, before a complaint or regulator does the review instead.

Incident-day readiness

A playbook with roles, clocks and drafted notifications — because the legal cost of a breach is set mostly in its first hours.

A typical engagement: a business using AI tools across marketing and HR discovers, through the mapping, that employee data collected for payroll feeds an analytics model under no valid basis. The flow is restructured, the consents corrected, and an incident playbook installed — ahead of any complaint.

Described in abbreviated, anonymised form to preserve client confidentiality.

Does Israeli privacy law apply to AI processing of personal data?

Yes — Israel's Protection of Privacy framework governs personal data regardless of the technology processing it, including registration, security and use-limitation duties. AI changes the risk profile and the scale, not the applicability.

Can we use customer data to train or feed AI models?

Only within the basis on which it was collected — purpose limitation is the controlling principle. Data gathered for service delivery does not automatically extend to model training or profiling; the gap between collected-for and used-for is where enforcement concentrates.

What should the first day of an AI data incident look like?

Containment, preservation and assessment in parallel: stop the flow, freeze the evidence, and establish what data and whose. Notification duties run on short clocks once thresholds are met — which is why the playbook, roles and draft notices must exist before the incident does.

Start a conversation.

The firm replies within one business day.